lith #
Secrets and runtime env for the Aesthetic Computer monolith deploy.
lith/deploy.fish expects:
aesthetic-computer-vault/lith/.env
That file is uploaded to:
/opt/ac/system/.env
Why system/.env on the server:
lith.serviceusesEnvironmentFile=/opt/ac/system/.env- The monolith serves the main site and API from the shared
system/tree
Minimum required keys:
NODE_ENV=productionCONTEXT=productionDEPLOY_SECRET=...
Optional product analytics keys:
POSTHOG_PROJECT_TOKEN=phc_...— enables the privacy-minimized browser clientPOSTHOG_API_HOST=https://us.i.posthog.com— US or EU Cloud ingestion hostPOSTHOG_SERVER_ENDPOINT_EVENTS=true— separately enables anonymous endpoint aggregatesPOSTHOG_OSKIEWAR_EVENTS=true— separately enables minimized Oskiewar server milestones
See docs/POSTHOG.md for the endpoint inventory, privacy
contract, event schemas, validation, and rollback.
Recommended workflow:
- Copy
.env.exampleto.env - Fill in the real production values
- Re-run
fish vault-tool.fish statusto confirmlith/.envis tracked - Deploy with
fish /workspaces/aesthetic-computer/lith/deploy.fish
Easel inference configuration #
Production loads OPENROUTER_API_KEY from
/etc/aesthetic-computer/easel-inference.env through
/etc/systemd/system/lith.service.d/40-easel-inference.conf. This separate,
root-only environment survives deploys that replace /opt/ac/system/.env with
an older fleet copy. Keep it synchronized when rotating the key in the vault's
lith/.env, then restart lith. The vault lith/.env.keys manifest also requires
this key so deployment validation rejects incomplete environments.